Junglewise Threat Intelligence

CVE-2025-39873: Linux Kernel Xilinx CAN use-after-free in xcan_write_frame

CVE-2025-39873 · Severity: high · CVSS 7.8 · Published 2025-09-23

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Xilinx CAN network driver, which manages communication for industrial and automotive hardware. A flaw in how the driver handles network data packets could allow a local attacker to cause a system crash or potentially execute unauthorized code. This issue affects systems using Xilinx CAN controllers and has been addressed in recent kernel updates.

Technical details

A use-after-free (UAF) vulnerability exists in the xcan_write_frame() function of the Xilinx CAN driver. The root cause is an incorrect sequence of operations where can_put_echo_skb() is called before the driver has finished accessing the socket buffer (SKB). Since can_put_echo_skb() transfers ownership of the SKB, it may be freed while the driver still holds a reference to it. An attacker with local access could exploit this race condition to trigger memory corruption. The fix involves reordering the function calls to ensure can_put_echo_skb() is only invoked after all driver operations on the SKB are complete. Patches are available for multiple stable kernel branches including 5.15, 6.1, 6.6, and 6.12.

Affected products

  • Linux Linux Kernel 4.19 to 5.15.194, 6.1.153, 6.6.107, 6.12.48, 6.16.8

Timeline

  • 2025-08-22: patched: Initial patch submitted by Anssi Hannula
  • 2025-09-23: disclosed: CVE published

References

Related threats